owncloud
168 tracked vulnerabilities.
CVE-2020-10254
MEDIUM
owncloud < 10.4.0 - Unauthenticated Authentication Bypass via Image Preview
Feb 19, 2021
CVSS 5.9
EPSS 0.00
CVE-2020-10252
HIGH
owncloud < 10.4.0 - Authenticated Server-Side Request Forgery via Files Sharing External Remote Parameter
Feb 19, 2021
CVSS 8.3
EPSS 0.01
CVE-2020-28645
CRITICAL
owncloud < 10.6.0 - Unauthenticated Arbitrary File Deletion via User Deletion
Feb 09, 2021
CVSS 9.1
EPSS 0.00
CVE-2020-28644
MEDIUM
owncloud < 10.6.0 - Cross-Site Request Forgery in OCS API Endpoints
Feb 09, 2021
CVSS 4.3
EPSS 0.00
CVE-2020-16144
MEDIUM
ownCloud files_antivirus < 0.15.2 - Virus File Deletion Failure via Public Link Upload
Feb 09, 2021
CVSS 5.7
EPSS 0.00
CVE-2020-16255
MEDIUM
owncloud < 10.5 - Cross-Site Scripting in Login Page Forgot Password Functionality
Jan 15, 2021
CVSS 6.1
EPSS 0.00
CVE-2019-25337
CRITICAL
OwnCloud 8.1.8 - Username Enumeration via Share Endpoint Wildcard Search
Feb 12, 2026
CVSS 9.8
EPSS 0.00
CVE-2017-9340
MEDIUM
ownCloud Server <10.0.2 - Privilege Escalation
Jul 17, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-9339
MEDIUM
ownCloud Server <10.0.2 - Info Disclosure
Jul 17, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-9338
MEDIUM
ownCloud Server <8.2.12, <9.0.10, <9.1.6, <10.0.2 - XSS
Jul 17, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-8896
MEDIUM
ownCloud Server <8.2.12, <9.0.10, <9.1.6, <10.0.2 - XSS
Jul 17, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-5867
MEDIUM
ownCloud < 8.1.11, 8.2.x < 8.2.9, 9.0.x < 9.0.7, 9.1.x < 9.1.3 - Authenticated Denial of Service via One-Bit BMP File
Mar 03, 2017
CVSS 6.5
EPSS 0.01
CVE-2017-5866
MEDIUM
Owncloud < 8.1.10 - Information Disclosure
Mar 03, 2017
CVSS 4.3
EPSS 0.00
CVE-2017-5865
LOW
ownCloud < 8.1.11, 8.2.x < 8.2.9, 9.0.x < 9.0.7, 9.1.x < 9.1.3 - User Enumeration via Password Reset Error Messages
Mar 03, 2017
CVSS 3.7
EPSS 0.00
CVE-2016-9468
MEDIUM
Nextcloud Server <9.0.54, 10.0.1 & ownCloud Server <9.0.6, 9.1.2 - Content Spoofing via DAV
Mar 28, 2017
CVSS 5.3
EPSS 0.00
CVE-2016-9467
MEDIUM
Nextcloud Server < 9.0.54 and 10.0.1 & ownCloud Server < 9.0.6 and 9.1.2 - Content Spoofing in Files App Location Bar
Mar 28, 2017
CVSS 5.3
EPSS 0.01
CVE-2016-9466
MEDIUM
Nextcloud Server < 10.0.1 and ownCloud Server < 9.0.6 and 9.1.2 - Reflected Cross-Site Scripting in Gallery Application
Mar 28, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-9465
MEDIUM
Nextcloud Server < 10.0.1 & ownCloud Server < 9.0.6 and 9.1.2 - Stored Cross-Site Scripting in CardDAV Image Export
Mar 28, 2017
CVSS 5.4
EPSS 0.00
CVE-2016-9463
HIGH
Nextcloud Server <9.0.54/10.0.1 & ownCloud Server <9.1.2/9.0.6/8.2.9 - SMB Auth Bypass
Mar 28, 2017
CVSS 8.1
EPSS 0.04
CVE-2016-9462
MEDIUM
Nextcloud Server < 9.0.52 & ownCloud Server < 9.0.4 - Unauthenticated File Restore Privilege Bypass
Mar 28, 2017
CVSS 4.3
EPSS 0.00
CVE-2016-9461
MEDIUM
Nextcloud Server < 9.0.52 & ownCloud Server < 9.0.4 - Authenticated Arbitrary File Write via WebDAV COPY
Mar 28, 2017
CVSS 4.3
EPSS 0.01
CVE-2016-9460
MEDIUM
Nextcloud Server < 9.0.52 and ownCloud Server < 9.0.4 - Content Spoofing in Files App Location Bar
Mar 28, 2017
CVSS 5.3
EPSS 0.00
CVE-2016-9459
MEDIUM
Nextcloud Server < 9.0.52 and ownCloud Server < 9.0.4 - Stored Cross-Site Scripting via Download Log
Mar 28, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-7102
HIGH
owncloud_desktop_client < 2.2.2 - Local Code Execution via Trojan Library in Special Path
Jan 23, 2017
CVSS 8.4
EPSS 0.00
CVE-2016-5876
MEDIUM
ownCloud <8.2.6 & <9.0.3 - Info Disclosure
Jan 23, 2017
CVSS 5.9
EPSS 0.00